• Support
  • Login
  • Contact
  • Blog
  • Support
  • Login
  • Contact
  • Blog
SecurityScorecard SecurityScorecard
  • Products
    PRODUCTS
    • Security Ratings
      Identify security strengths across ten risk factors.
    • Security Data
      Get actionable, data-based insights.
    • Security Assessments
      Automate security questionnaire exchange.
    • Attack Surface Intelligence
      NEW
      On-demand contextualized global threat intelligence.
    • Automatic Vendor Detection
      Uncover your third and fourth party vendors.
    • Cyber Risk Quantification
      Translate cyber risk into financial impact.
    • Reporting Center
      Streamline cyber risk reporting.
    • SecurityScorecard Marketplace
      Discover and deploy pre-built integrations.
    SERVICES
    • Active Security Services
      Test your security controls.
    • Cyber Risk Intelligence
      Partner to obtain meaningful threat intelligence.
    • Digital Forensics & Incident Response
      Prepare to respond to any threat.
    • Third-Party Risk Management
      Reduce risk across your vendor ecosystem.
    BUY NOW
    • Compare All Plans
      Choose a plan that's right for your business.
    • Try Free Account
      Make informed decisions with confidence.
    • Buy Pro Now
      Add automated event responses.
    • Buy Business Now
      Expand on Pro with vendor management and integrations.
    • Request Enterprise Demo
      See the capabilities of an enterprise plan in action.
    icon__SSClogoMark icon__SSClogoMark

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Solutions
    BY USE CASE
    • Compliance
    • Cyber Insurance
    • Digital Forensics
    • Due Diligence
    • Enterprise Cyber Risk
    • Executive-Level Reporting
    • Incident Response
    • Regulatory Oversight
    • Third-Party Risk
    BY INDUSTRY
    • Critical Infrastructure
    • Enterprise
    • Financial Services
    • Government
    • Healthcare
    • Insurance
    • Retail & Consumer
    • Technology
    Help your organization calculate its risk
    View All Solutions
  • Customers
    OUR CUSTOMERS
    • Customer Overview
      Trusted by companies of all industries and sizes.
    • Peer Reviews
      Find out what our customers are saying.
    SUCCESS AND SUPPORT
    • Customer Success
      Receive award-winning customer service.
    • Support
      Get your questions answered by our experts.
    COMMUNITY
    • SecurityScorecard Connect
      Engage in fun, educational, and rewarding activities.
    • Connect Login
      Join our exclusive online customer community.
    icon__SSClogoMark icon__SSClogoMark
    Understand and reduce risk with SecurityScorecard.
    Free account sign up
  • Partners

    Partner Program Overview

    Partner with SecurityScorecard and leverage our global cybersecurity ratings leadership to expand your solution, deliver more value, and win new business.

    Learn more
    • Locate a Partner
      Access our industry-leading partner network.
    • Value-Added Resellers
      Enter new markets, deliver more value, and get rewarded.
    • Managed Service Providers
      Meet customer needs with cybersecurity ratings.
    • ISAC Partner Program
      Learn more about the industries we support and ISAC member benefits.
    • Technology Alliances
      Access innovative solutions from leading providers.
    • SCORE Portal Login
      Use the SCORE Partner Program to grow your business.
    • SecurityScorecard Marketplace
      Find a trusted solution that extends your SecurityScorecard experience.

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Resources
    RESOURCES
    • Resource Center
      Explore our cybersecurity ebooks, data sheets, webinars, and more.
    • SecurityScorecard Blog
      Read the latest blog posts published weekly.
    • Research & Insights Center
      Access our research on the latest industry trends and sector developments.
    • SecurityScorecard Academy
      NEW
      Complete certification courses and earn industry-recognized badges.
    TOOLS AND DOCUMENTATION
    • Free Security Rating
      Get your free ratings report with customized security score.
    • Product Release Notes
      Visit our support portal for the latest release notes.
    • Free Account Signup
      Start monitoring your cybersecurity posture today.
    • Chrome Extension
      NEW
      Show the security rating of websites you visit.
    • Assessments ROI Calculator
      Calculate the ROI of automating questionnaires.
    Trust begins with transparency. Take a look at the data that drives our ratings.
    Learn more
  • Company

    Working at SecurityScorecard

    Committed to promoting diversity, inclusion, and collaboration–and having fun while doing it.

    Join our team
    • About Us
      SecurityScorecard is the global leader in cybersecurity ratings.
    • Leadership
      Meet the team that is making the world a safer place.
    • Press
      Explore our most recent press releases and coverage.
    • Events
      Join us at any of these upcoming industry events.
    • Policy Insights
      Raising the bar on cybersecurity with security ratings.
    • Careers
      APPLY TODAY
      Come join the SecurityScorecard team!
    • Contact Us
      Contact us with any questions, concerns, or thoughts.
    • Trust Portal
      Take an inside look at the data that drives our technology.
    • Help Center
      We are here to help with any questions or difficulties.
Request a demo
SecurityScorecard SecurityScorecard
  • Support
  • Login
  • Contact
  • Blog
  • Support
  • Login
  • Contact
  • Blog
SecurityScorecard SecurityScorecard
  • Products
    PRODUCTS
    • Security Ratings
      Identify security strengths across ten risk factors.
    • Security Data
      Get actionable, data-based insights.
    • Security Assessments
      Automate security questionnaire exchange.
    • Attack Surface Intelligence
      NEW
      On-demand contextualized global threat intelligence.
    • Automatic Vendor Detection
      Uncover your third and fourth party vendors.
    • Cyber Risk Quantification
      Translate cyber risk into financial impact.
    • Reporting Center
      Streamline cyber risk reporting.
    • SecurityScorecard Marketplace
      Discover and deploy pre-built integrations.
    SERVICES
    • Active Security Services
      Test your security controls.
    • Cyber Risk Intelligence
      Partner to obtain meaningful threat intelligence.
    • Digital Forensics & Incident Response
      Prepare to respond to any threat.
    • Third-Party Risk Management
      Reduce risk across your vendor ecosystem.
    BUY NOW
    • Compare All Plans
      Choose a plan that's right for your business.
    • Try Free Account
      Make informed decisions with confidence.
    • Buy Pro Now
      Add automated event responses.
    • Buy Business Now
      Expand on Pro with vendor management and integrations.
    • Request Enterprise Demo
      See the capabilities of an enterprise plan in action.
    icon__SSClogoMark icon__SSClogoMark

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Solutions
    BY USE CASE
    • Compliance
    • Cyber Insurance
    • Digital Forensics
    • Due Diligence
    • Enterprise Cyber Risk
    • Executive-Level Reporting
    • Incident Response
    • Regulatory Oversight
    • Third-Party Risk
    BY INDUSTRY
    • Critical Infrastructure
    • Enterprise
    • Financial Services
    • Government
    • Healthcare
    • Insurance
    • Retail & Consumer
    • Technology
    Help your organization calculate its risk
    View All Solutions
  • Customers
    OUR CUSTOMERS
    • Customer Overview
      Trusted by companies of all industries and sizes.
    • Peer Reviews
      Find out what our customers are saying.
    SUCCESS AND SUPPORT
    • Customer Success
      Receive award-winning customer service.
    • Support
      Get your questions answered by our experts.
    COMMUNITY
    • SecurityScorecard Connect
      Engage in fun, educational, and rewarding activities.
    • Connect Login
      Join our exclusive online customer community.
    icon__SSClogoMark icon__SSClogoMark
    Understand and reduce risk with SecurityScorecard.
    Free account sign up
  • Partners

    Partner Program Overview

    Partner with SecurityScorecard and leverage our global cybersecurity ratings leadership to expand your solution, deliver more value, and win new business.

    Learn more
    • Locate a Partner
      Access our industry-leading partner network.
    • Value-Added Resellers
      Enter new markets, deliver more value, and get rewarded.
    • Managed Service Providers
      Meet customer needs with cybersecurity ratings.
    • ISAC Partner Program
      Learn more about the industries we support and ISAC member benefits.
    • Technology Alliances
      Access innovative solutions from leading providers.
    • SCORE Portal Login
      Use the SCORE Partner Program to grow your business.
    • SecurityScorecard Marketplace
      Find a trusted solution that extends your SecurityScorecard experience.

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Resources
    RESOURCES
    • Resource Center
      Explore our cybersecurity ebooks, data sheets, webinars, and more.
    • SecurityScorecard Blog
      Read the latest blog posts published weekly.
    • Research & Insights Center
      Access our research on the latest industry trends and sector developments.
    • SecurityScorecard Academy
      NEW
      Complete certification courses and earn industry-recognized badges.
    TOOLS AND DOCUMENTATION
    • Free Security Rating
      Get your free ratings report with customized security score.
    • Product Release Notes
      Visit our support portal for the latest release notes.
    • Free Account Signup
      Start monitoring your cybersecurity posture today.
    • Chrome Extension
      NEW
      Show the security rating of websites you visit.
    • Assessments ROI Calculator
      Calculate the ROI of automating questionnaires.
    Trust begins with transparency. Take a look at the data that drives our ratings.
    Learn more
  • Company

    Working at SecurityScorecard

    Committed to promoting diversity, inclusion, and collaboration–and having fun while doing it.

    Join our team
    • About Us
      SecurityScorecard is the global leader in cybersecurity ratings.
    • Leadership
      Meet the team that is making the world a safer place.
    • Press
      Explore our most recent press releases and coverage.
    • Events
      Join us at any of these upcoming industry events.
    • Policy Insights
      Raising the bar on cybersecurity with security ratings.
    • Careers
      APPLY TODAY
      Come join the SecurityScorecard team!
    • Contact Us
      Contact us with any questions, concerns, or thoughts.
    • Trust Portal
      Take an inside look at the data that drives our technology.
    • Help Center
      We are here to help with any questions or difficulties.
Request a demo
SecurityScorecard SecurityScorecard
BLOG

What is APRA CPS 234?

Miryam Amsili Meir
04/22/2021

Financial services organizations have long been a target for malicious actors. In November 2020, the Australian Prudential Regulation Authority (APRA) announced that it would be strengthening its enforcement of Cross-Industry Prudential Standard (CPS) 234. Although CPS 234 has been around since 2018, the regulatory body has remained lenient in its enforcement. However, with more stringent enforcement on the horizon, understanding the APRA CPS 234 becomes more important for organizations that need to prove compliance.

What is APRA CPS 234?

APRA is the regulatory authority for Australia’s financial services industry. CPS 234 sets out a series of guidelines for financial services organizations so that they can maintain cybersecurity resiliency and continue to protect sensitive data.

CPS 234 has four key requirements:

  • Define information security-related roles and responsibilities
  • Maintain a risk-based security posture that enables business continuity in response to cybersecurity incidents
  • Implement security controls aligned with data asset criticality and sensitivity
  • Notify APRA of information security incidents

Who does the APRA Prudential Standard apply to?

At a high level, CPS 234 applies to any APRA-regulated entity. The standard falls under sections of the following laws:

  • The Banking Act of 1959 (Banking Act)
  • The Insurance Act of 1973 (Insurance Act)
  • The Life Insurance Act of 1995 (Life Insurance Act)
  • The Private Health Insurance (Prudential Supervision) Act of 2015 (PHIPS Act
  • The Superannuation Industry (Supervision) Act of 1993 (SIS Act)

On a more detailed level, CPS 234 specifically references the following:

  • Banks:
    • Authorized deposit-taking institutions (ADIs)
    • Non-operating holding companies authorized under the Banking Act (authorized banking NOHCs);
  • General and Life Insurers:
    • General insurers
    • Non-operating holding companies authorized under the Insurance Act (authorized insurance NOHCs)
    • Parent entities of Level 2 insurance groups;
    • Life companies, including friendly societies, eligible foreign life insurance companies (EFLICs)
    • Non-operating holding companies registered under the Life Insurance Act (registered life NOHCs);
    • Private health insurers registered under the PHIPS Act;
    • RSE licensees under the SIS Act

What are the primary requirements for complying with the APRA Prudential Standard CPS?

CPS 234 consists of thirty-six paragraphs, twenty-four of which discuss how the governing body expects covered organizations to mature their security programs. Within those twenty-four paragraphs, nine basic requirements outline how APRA expects covered organizations can better secure data.

Roles and responsibilities

Under this standard, organizations need to assign cybersecurity responsibilities across all leadership and departments. This includes:

  • Assurance by Board of Directors that organization maintains appropriate risk-based information security program
  • Clearly defining information security-related roles and responsibilities across Board of Directors, senior management, governing bodies, and other decision-making stakeholders

Specifically, CPS 234 requires robust governance by the covered entity’s Board of Directors.

Information security capability

The information security capability requirement focuses on creating governance capabilities and documentation. This includes:

  • Establishing a risk-based capability for continued business operations
  • Establishing a third-party risk management process
  • Continuous monitoring over its information security capability to address new vulnerability and threat risks

At this level, covered entities should be focusing on how to maintain resiliency by ensuring they understand all risk to their data, including supply chain cybersecurity risk. In a footnote, APRA specifically points out:

For the avoidance of doubt, paragraph 16 of this Prudential Standard applies to all information assets managed by related parties and third parties, not only those captured under agreements with service providers of outsourced material business activities.

This footnote indicates that covered entities should create a detailed list of all third parties with whom they do business or share customer information.

Policy framework

Taking risk into account, all regulated entities need to maintain an information security policy framework. This includes:

  • Providing direction for responsible parties
  • Responsible parties include the Board, senior management, governing bodies, staff, contractors, consultants, related parties, third parties, and customers

Information asset identification and classification

Under CPS 234, covered entities need to ensure that they know what sensitive data they collect, store, and transmit. This includes:

  • Classifying data based on criticality and sensitivity
  • Identifying data managed by related parties and third parties
  • Classifying data should consider a security incident’s potential financial and non-financial impact to the interests of:
    • Covered entity
    • Depositors
    • Policyholders
    • Beneficiaries
    • Other customers

Implementation of controls

In order to protect data, covered entities need to put security controls in place for all data, including information managed by related parties and third parties. The controls implemented should be risk-based, taking the following into account:

  • Vulnerabilities and threats to data
  • Criticality and sensitivity of data
  • Life-cycle stage of data
  • Potential consequences of an incident
  • Related parties’ and third parties’ ability to secure data

Additionally, this section also incorporates a footnote that related parties and third parties are not confined to agreements and outsourced activities.

Incident management

Data protection must also consider how the covered entity responds to events. This includes:

  • Mechanisms for detecting and responding to incidents
  • Maintaining response plans that include likely threat scenarios
  • Mechanisms for all relevant stages from detection to post-incident review
  • Mechanisms for escalating and reporting incidents as part of proving governance
  • Annual program testing and review

Testing control effectiveness

Out of all the CPS 234 subsections, this one has the most details. Under this section, covered entities must:

  • Consider the following:
    • Threat risk changes
    • Data criticality and sensitivity
    • Security incident consequences
    • Potential risks from environments that the entity does not control
    • Materiality and frequency of data changes
  • Review related party and third party testing frequency and robustness
  • Escalate and report control deficiencies to the Board and senior management
  • Ensure independent specialists have the skills necessary
  • Review testing program sufficiency at least annually or when a material change to business environment or information assets occurs

Internal audit

In order to prove governance, all covered entities must conduct an independent audit. This should include:

  • Review of security control design and operating effectiveness
  • Review of related parties’ and third parties’:
    • Information security control assurance
    • Information security incident documentation
  • Ensure audit personnel have appropriate skills

APRA notification

Like many other information security requirements, APRA’s CPS 234 incorporates a section regarding incident notification. This includes:

  • Providing notification within 72 hours of discovering the incident for any event that:
    • Has potential to financially or non-financially materially impact entity, depositors, policyholders, beneficiaries, or other customers
    • Other regulators in Australia or elsewhere have been notified about
  • Providing APRA notification within 10 days of finding a material control weakness that cannot be remediated in a timely manner

SecurityScorecard for APRA CPS 234: Continuous monitoring and assurance

SecurityScorecard’s security ratings and Atlas platforms enable organizations to reduce the costs associated with APRA CSP 234 compliance. Our security ratings platform provides viability into covered entities’, related parties’, and third parties’ security posture across ten categories of risk, including patching cadence, IP reputation, DNS health, network security, web application security, and endpoint security.

Covered entities gain at-a-glance visibility into risk with SecurityScorecard’s easy-to-read security ratings that use an A-F scale. For organizations that need to engage in third party security monitoring, our Atlas platform leverages our security ratings’ risk data to compare questionnaire responses to the data we collect. This enables real-time assurance over third party risk for a more robust compliance program.


As organizations move toward enhancing their compliance programs to meet CPS 234 requirements, they can create an end-to-end program based on data and metrics by partnering with SecurityScorecard.

Return to Blog
Join us in making the world a safer place.
FREE ACCOUNT SIGN UP
Products
Solutions
Customers
Marketplace
Partners
Resources
Company
Trust Portal
Security Ratings
Login
Blog
Contact
Careers

SecurityScorecard
Tower 49
12 E 49th St
Suite 15-100
New York, NY 10017

[email protected]

United States: (800) 682-1701
International: +1(646) 809-2166
Social-linkedin Social-facebook Twitter Instagram Youtube